Review and harden security for htmx and server-driven web apps.

MITAuto-check passedSecurity

Install Htmx Security

skills CLI
$ npx skills add hashgraph-online/awesome-codex-plugins --skill htmx-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install hashgraph-online/awesome-codex-plugins htmx-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/hashgraph-online/awesome-codex-plugins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/LVTD-LLC/skills/skills/htmx-security .claude/skills/htmx-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
htmx-security
GitHub stars
1.2k
Token cost
~1.3k tokens
SKILL.md length
649 words
Files
3 (incl. assets)
Skills in repo
736
Repo updated
First seen
Licence
MIT

At a glance

Review and harden security for htmx and server-driven web apps.

  • Handling user-supplied HTML
  • SKILL.md covers Threat Model, Baseline Rules, User Content and htmx-Specific Risks, plus 6 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Sanitizing fragments

What it does

Htmx Security is an agent skill from hashgraph-online/awesome-codex-plugins. Review and harden security for htmx and server-driven web apps. Use when handling user-supplied HTML, escaping or sanitizing fragments, adding CSP, evaluating XSS risk, configuring CSRF or cookies, loading htmx from a CDN, using SRI hashes, accepting hx- attributes from content, or reviewing htmx request headers and history caching.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including assets (for example `agents/openai.yaml`). Compatibility notes: Codex, Claude Code, and other Agent Skills-compatible clients.

It sits in Security, covering Web application vulnerabilities and Caching. The repository describes itself as: A curated list of awesome OpenAI Codex / ChatGPT plugins, skills, and resources. The 1 Codex Marketplace. See live plugins at: https://hol.org/plugins/best-codex-plugins. The licence is MIT.

When your agent uses it

  • Handling user-supplied HTML
  • Sanitizing fragments
  • Evaluating XSS risk
  • Configuring CSRF

Example prompts

  • “/htmx-security”

Requirements

  • Compatibility (from SKILL.md): Codex, Claude Code, and other Agent Skills-compatible clients.

What it can do on your machine

Read from SKILL.md and the folder at commit 16b4156. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Codex, Claude Code, and other Agent Skills-compatible clients.

    From compatibility in the SKILL.md frontmatter.

Context cost

Htmx Security loads about 1.3k tokens when it runs. Until then it costs about 87 tokens; SKILL.md has 649 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~87
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from hashgraph-online/awesome-codex-plugins at commit 16b4156, republished under its MIT licence (© hashgraph-online). 649 words, ~1,306 tokens.

Download SKILL.mdSave it as .claude/skills/htmx-security/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
htmx-security
description
Review and harden security for htmx and server-driven web apps. Use when handling user-supplied HTML, escaping or sanitizing fragments, adding CSP, evaluating XSS risk, configuring CSRF or cookies, loading htmx from a CDN, using SRI hashes, accepting hx-* attributes from content, or reviewing htmx request headers and history caching.
compatibility
Codex, Claude Code, and other Agent Skills-compatible clients.
license
MIT
metadata.version
0.1.0
metadata.displayName
htmx Security
metadata.category
Frontend
metadata.tags
htmx,security,xss,csp,frontend

htmx Security

Use this skill before shipping htmx features that render user content, accept rich HTML, add third-party scripts, change Content Security Policy, or expose new mutation endpoints.

Threat Model

htmx keeps rendering on the server, but unsafe HTML is still unsafe HTML. A fragment swap can insert scripts, event handlers, dangerous URLs, or htmx attributes that cause requests. Treat every fragment as executable browser surface unless it is escaped or sanitized.

Baseline Rules

  • Escape user-supplied text by default.
  • Sanitize rich HTML on the server with a strict allowlist.
  • Strip or block hx-*, data-hx-*, hx-on, inline event handlers, script, dangerous URLs, and style features that the product does not explicitly allow.
  • Keep auth, authorization, and validation on the server.
  • Use CSRF protection for same-origin mutations.
  • Do not put secrets, privileged object IDs, or authorization decisions in HTML attributes.
  • Keep htmx requests same-origin unless CORS, CSRF, cookies, and credentials are deliberately designed.

User Content

Choose one content policy:

User content typePolicy
Plain textEscape and render as text
MarkdownRender through a sanitizer and allow only safe tags/attributes
Rich HTMLSanitize with a narrow allowlist and strip htmx/event/script capabilities
Trusted admin HTMLStill sanitize unless the trust boundary is documented and access is tightly controlled

Do not mark content safe merely because it was stored in the database earlier.

htmx-Specific Risks

  • User-controlled hx-get, hx-post, hx-put, hx-patch, hx-delete, or hx-trigger can create unintended requests.
  • User-controlled hx-on or inline handlers can execute JavaScript.
  • User-controlled hx-vals can smuggle unexpected parameters.
  • Fragment responses can replace more of the page than intended if targets are broad.
  • History caching can retain sensitive HTML on the client.

Use hx-history="false" on sensitive pages or containers that should not be stored in htmx history cache.

CSRF And Cookies

  • Prefer the framework's standard CSRF mechanism.
  • Configure htmx to send the CSRF header once in the base layout or startup script.
  • Keep CSRF tokens out of logs and analytics.
  • Use Secure, HttpOnly, and SameSite cookie settings appropriate to the app.
  • Avoid cross-site htmx mutations unless the app has a clear credential policy.

CDN And Script Loading

Prefer vendored static assets for reproducibility. If loading htmx or extensions from a CDN:

  • pin the exact version;
  • include Subresource Integrity where possible;
  • set crossorigin when required by SRI;
  • document why CDN loading is acceptable for the app;
  • monitor version changes deliberately rather than floating to latest.
Show full SKILL.md (257 more words)Show less

Content Security Policy

Design CSP around the actual frontend stack:

  • htmx can work with a strict CSP when inline scripts and unsafe eval are avoided.
  • Inline event handlers, hx-on, Alpine default builds, and _hyperscript can require looser policies unless replaced with CSP-compatible patterns.
  • Start with report-only mode for existing apps, then tighten.
  • Include reporting endpoints only when someone reviews reports.
  • Test swapped fragments under the final CSP, not just the initial page load.

Review Checklist

  • Are all mutation endpoints protected by auth, authorization, and CSRF?
  • Does every endpoint re-check permissions server-side?
  • Are user values escaped in fragments and full pages?
  • Is any rich content sanitized with an allowlist?
  • Can user content inject hx-*, hx-on, event handlers, scripts, or dangerous URLs?
  • Are sensitive fragments excluded from htmx history cache?
  • Are third-party scripts pinned and integrity-checked?
  • Does CSP match Alpine, _hyperscript, and htmx usage?
  • Do tests cover both htmx and non-htmx paths?

Testing Ideas

  • Submit text containing HTML tags and confirm it renders as text.
  • Submit sanitized rich content with attempted event handlers and htmx attributes.
  • Attempt unauthorized htmx mutations directly with forged headers.
  • Verify login redirects do not get swapped into small targets.
  • Run browser checks with CSP enabled and inspect violations.

Avoid

  • Do not rely on htmx headers as proof of trust.
  • Do not trust hidden inputs, hx-vals, or client-side state for authorization.
  • Do not allow user-authored htmx attributes in normal rich content.
  • Do not loosen CSP globally to fix one component without documenting the tradeoff.
  • Do not expose JSON or HTML endpoints with different authorization assumptions.

© hashgraph-online, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (assets) in plugins/LVTD-LLC/skills/skills/htmx-security of hashgraph-online/awesome-codex-plugins.

  • SKILL.md
  • agents/openai.yaml
  • assets/icons8-code.svg

Open the folder on GitHubat commit 16b4156

Compare with similar skills

Htmx Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Htmx Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Htmx Security this skillhashgraph-online/awesome-codex-plugins1.2k—~1.3kAutomated safety check: PassMIT
Security Guidancealirezarezvani/claude-skills28k—~1.9kAutomated safety check: PassMIT
Security And Hardeningpenpot/penpot61k6 repos~4.7kAutomated safety check: NotesMPL-2.0
Security Auditoreigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0
Security Reviewjewbetcha/opentrace11617 repos~3.1kAutomated safety check: NotesMIT
Strix Code Vulnerability Scanusestrix/strix67k—~1.1kAutomated safety check: PassApache-2.0

Similar skills

  • Security Guidance

    alirezarezvani/claude-skills

    PreToolUse security-anti-pattern hook for Claude Code. An agent skill from alirezarezvani/claude-skills.

    28k GitHub stars~1.9k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Hardens code against vulnerabilities. An agent skill from penpot/penpot.

    61k GitHub starsUsed in 6 repos~4.7k tokens
    SecurityAuto-check: notes
  • Security Auditor

    eigent-ai/eigent

    Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

    15k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check: notes
  • Security Review

    jewbetcha/opentrace

    A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.

    116 GitHub starsUsed in 17 repos~3.1k tokens
    SecurityAuto-check: notes
  • Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept.

    67k GitHub stars~1.1k tokensUpdated today
    SecurityAuto-check passed
  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    893 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed

More from hashgraph-online/awesome-codex-plugins

All 736 skills in this repo
  • Anime Reaction Gif

    hashgraph-online/awesome-codex-plugins

    Create original anime-style reaction stickers as looping GIFs and MP4 previews, using generated character pose sheets and timed key poses.

    1.2k GitHub stars~922 tokensUpdated yesterday
    Auto-check passed
  • Calibredb

    hashgraph-online/awesome-codex-plugins

    Manage and query Calibre libraries with the calibredb CLI (local paths or Calibre Content server URLs).

    1.2k GitHub stars~1k tokensUpdated yesterday
    Auto-check passed
  • Rust API Test Harness

    hashgraph-online/awesome-codex-plugins

    A skill your agent uses when adding, changing, testing, or debugging Rust HTTP APIs and services, especially when Codex needs black-box integration tests, random-port app startup, real database test…

    1.2k GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed
  • Art

    hashgraph-online/awesome-codex-plugins

    Make a studio's game look like something at build time — a cover from a real frame of the game (free), painted covers, backdrops, textures and character plates from image models through the…

    1.2k GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Calle

    hashgraph-online/awesome-codex-plugins

    Use CALL-E from Codex through the calle CLI. An agent skill from hashgraph-online/awesome-codex-plugins.

    1.2k GitHub stars~2.9k tokensUpdated yesterday
    Auto-check passed
  • Game Balance Economy

    hashgraph-online/awesome-codex-plugins

    Balance game difficulty, resources, rewards, probability, progression, economies, and dominant strategies.

    1.2k GitHub stars~618 tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Htmx Security

What does Htmx Security do?

Review and harden security for htmx and server-driven web apps. Htmx Security is an agent skill from hashgraph-online/awesome-codex-plugins. Review and harden security for htmx and server-driven web apps.

When should I use Htmx Security?

Htmx Security fits situations like: handling user-supplied HTML; sanitizing fragments; evaluating XSS risk; configuring CSRF.

How do I install Htmx Security in Claude Code?

Run `npx skills add hashgraph-online/awesome-codex-plugins --skill htmx-security -a claude-code`. Or copy the skill folder (plugins/LVTD-LLC/skills/skills/htmx-security in hashgraph-online/awesome-codex-plugins) into .claude/skills/htmx-security in your project. Claude Code loads it when a task matches its description.

How do I install Htmx Security in Codex?

Run `npx skills add hashgraph-online/awesome-codex-plugins --skill htmx-security -a codex`. Or copy the skill folder (plugins/LVTD-LLC/skills/skills/htmx-security in hashgraph-online/awesome-codex-plugins) into .agents/skills/htmx-security in your project. Codex loads it when a task matches its description.

Can I use Htmx Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hashgraph-online/awesome-codex-plugins --skill htmx-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/htmx-security, .gemini/skills/htmx-security, .github/skills/htmx-security and .opencode/skills/htmx-security in your project.

What does Htmx Security need to run?

SKILL.md names no scripts, command-line tools or credentials: Htmx Security is instructions for the agent only. Compatibility (from SKILL.md): Codex, Claude Code, and other Agent Skills-compatible clients..

Does Htmx Security access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Htmx Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Htmx Security use?

Htmx Security is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Htmx Security use?

About 1.3k tokens (SKILL.md is roughly 5.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Htmx Security?

Skills that share tags, products or a category with Htmx Security: Security Guidance (alirezarezvani/claude-skills, 28k stars), Security And Hardening (penpot/penpot, 61k stars), Security Auditor (eigent-ai/eigent, 15k stars) and Security Review (jewbetcha/opentrace, 116 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Htmx Security?

hashgraph-online (a GitHub organization) maintains it in hashgraph-online/awesome-codex-plugins, which has 1,232 GitHub stars. The repository holds 736 skills in this directory. The repository was last updated on October 6, 2026.

Source: hashgraph-online/awesome-codex-plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.